CVE-2025-54292: Client-Side Path Traversal in LXD-UI
Path traversal in Canonical LXD LXD-UI versions before 6.5 and 5.21.4 on all platforms allows remote authenticated attackers to access or modify unintended resources via crafted resource names embedded in URL paths.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54292?
CVE-2025-54292 is considered a medium-severity vulnerability due to its potential to allow unauthorized access to resources.
How do I fix CVE-2025-54292?
To fix CVE-2025-54292, upgrade Canonical LXD-UI to versions 6.5 or higher, or 5.21.4 or higher.
Who is affected by CVE-2025-54292?
CVE-2025-54292 affects all platforms running Canonical LXD-UI versions before 6.5 and 5.21.4.
What kind of attack can exploit CVE-2025-54292?
CVE-2025-54292 can be exploited by remote authenticated attackers through crafted resource names in URL paths.
What are the implications of CVE-2025-54292?
The implications of CVE-2025-54292 include unauthorized access or modification of unintended resources in the affected versions.